Asterrr's Handbook

The SCS-C03 exam

Format, domain weights, what changed from SCS-C02, and a method for security scenario questions.

Format

65 questions
50 are scored and 15 are unscored pretest items. You can't tell which are which.
170 minutes
About 2.6 minutes per question. Questions are shorter than on the Professional exams.
750 / 1000
Scaled passing score. Scoring is compensatory, so you don't need to pass every domain.
No penalty
Unanswered questions count as wrong. Always pick something.
4 question types
Multiple choice, multiple response, ordering and matching. Ordering and matching need every item right.
Dec 2025
SCS-C03 replaced SCS-C02 on December 2, 2025.

Where the points are

DomainWeightIn one sentence
1 · Detection16%Monitoring, alerting and logging across an account or organization, and fixing them when they break
2 · Incident response14%Designing and testing a response plan, then responding to real events
3 · Infrastructure security18%Edge services, compute workloads and network controls
4 · Identity and access management20%Authentication and authorization, and troubleshooting both
5 · Data protection18%Data in transit, data at rest, and the keys, secrets and credentials behind them
6 · Security foundations and governance14%Account structure, consistent deployment and compliance evaluation

IAM is now the heaviest domain. Almost every question in other domains also has an IAM angle: the automation role that needs kms:Decrypt, the log bucket policy that must trust a service principal, the SCP that blocks the fix.

What changed from SCS-C02

AreaChange
Domains 1 and 2"Threat detection and incident response" and "Security logging and monitoring" became Detection and Incident response
Domain 6Renamed from "Management and security governance" to Security foundations and governance
WeightsIAM up from 16% to 20%. Infrastructure security down from 20% to 18%. Detection 16%, incident response 14%
New skillsValidating findings to assess scope and impact, OCSF and third-party WAF rules, guardrails for generative AI, inter-node encryption in transit, imported vs AWS generated key material, masking sensitive data, keys and certificates across Regions
RemovedASFF details, host-based firewalls, basic TCP/IP and TLS concepts, policy element basics, S3 static website hosting

How to read a security question

Phrase in the questionWhat it points to
Least privilegeNarrow actions and resources, conditions on the policy. Rules out * and broad managed policies
Across all accounts / the organizationDelegated administrator, organization trails, SCPs and RCPs, Firewall Manager, StackSets
Least operational overheadManaged detections and managed rules over custom Lambda functions and agents
Must not be able to delete or changeObject Lock in compliance mode, Backup Vault Lock, SCPs that deny the action, a separate log archive account
Must be able to prove / auditCloudTrail (with log file validation), Config, Audit Manager evidence
As quickly as possible (incident)Contain first: revoke sessions, isolate the instance, then investigate
Without traversing the internetVPC endpoints, PrivateLink, Direct Connect

Exam signal

When two options are both secure, the answer is usually the one that uses a managed control built for the job and applies it centrally, not a script that has to run in every account.

Deleting the evidence

In incident questions, options that terminate the instance, delete the compromised user or rotate every key "immediately" can destroy what you need to investigate. Contain first (deny, isolate, snapshot), then eradicate.

If your material is older

Older material saysUse now
AWS SSOIAM Identity Center
CloudFront Origin Access Identity (OAI)Origin Access Control (OAC)
AWS WAF ClassicAWS WAF (the current version)
Amazon Kinesis Data FirehoseAmazon Data Firehose
Personal Health DashboardAWS Health Dashboard
DynamoDB Encryption ClientAWS Database Encryption SDK
AWS Security Finding Format (ASFF) as an exam topicOpen Cybersecurity Schema Framework (OCSF), used by Security Lake and Security Hub
Scenario
A question ends: '…Which solution meets these requirements with the LEAST privilege?' One option attaches the AWS managed ReadOnlyAccess policy to the auditors' role. Another attaches a customer managed policy allowing only cloudtrail:LookupEvents and s3:GetObject on the log bucket. A third adds the auditors to the Administrators group with an SCP that denies writes. Which should you choose?

Further reading

On this page